Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

darkreading+1helpnetsecuritydarkreadingTwo critical zero-day vulnerabilities in Citrix NetScaler ADC and Gateway products have escalated from targeted espionage operations into widespread, opportunistic attacks, as threat actors race to exploit tens of thousands of unpatched devices worldwide.
CVE-2026-88771 and CVE-2026-88772, both carrying CVSS v4.0 scores of 9.5, were disclosed by Citrix on September 27 alongside patches for six additional flaws. But exploitation was well underway before that. Threat intelligence firm GreyNoise said it first detected zero-day exploitation attempts against a NetScaler Gateway on September 24, more than three days before Citrix's public advisory. WatchTowr Labs, which had warned of the attacks on September 26 based on credible intelligence, published a root-cause analysis and proof-of-concept exploit for CVE-2026-88771 shortly after disclosure — triggering a rapid shift from surgical targeting to mass scanning.darkreading+2
Xavier Bellekens, CEO of cyber deception firm Lupovis, told Help Net Security that exploitation attempts hit their sensor network "within minutes" of the PoC's release. "If you run NetScaler and you haven't patched, assume you are already being probed," he said.helpnetsecurity
The attack surface is vast. Censys identified roughly 42,000 internet-facing NetScaler hosts, with the United States accounting for 32% of exposures, followed by Germany at 13%. Palo Alto Networks separately counted more than 50,000 potentially vulnerable instances. Security researcher Kevin Beaumont said he has conducted firmware-version scanning and found fewer than 10% of exposed hosts are currently patched.unit42.paloaltonetworks+1
Beaumont also reported tracking over 100 victim organizations, each compromised with a unique webshell that cannot be remotely scanned for. He assessed the initial attackers' goal as espionage. The attack chain involves log poisoning to deploy webshells disguised behind fake stylesheet addresses, with exfiltrated data sent to external servers.helpnetsecurity
Benjamin Harris, founder and CEO of watchTowr, criticized Citrix for remaining silent as rumors circulated and administrators debated whether to take appliances offline. Patch files analyzed by watchTowr were dated September 24, suggesting the company had knowledge of exploitation days before its advisory. "Hours do matter," Harris told Dark Reading, noting that NetScaler's presence in critical infrastructure environments raises the stakes. "You've got an attacker that basically has a skeleton key to every organization running a Citrix NetScaler, and they're actually using it".darkreading
CISA has amplified Citrix's advisory, confirming that threat actors are exploiting the vulnerabilities globally. Organizations that cannot immediately apply the fixed builds — versions 14.1-73.37 and 13.1-64.23 — are being urged to take their NetScaler appliances offline.cisa+2